Our approach
We design Superlumy so that the most sensitive data — your voice and what you dictate — is exposed as little as possible. Audio isn't stored, dictation history stays on your device, and we never use your content to train AI models. Security is layered: we combine encryption, strict access controls, hardened infrastructure, and continuous monitoring.
Data protection
- Encryption in transit. All traffic between the app, website, and our servers is encrypted with TLS 1.2+.
- Encryption at rest. Data stored on our infrastructure is encrypted at rest using industry-standard algorithms.
- Data minimization. We collect only what we need to run the Service, and we retain it only as long as necessary.
Voice & on-device processing
- Audio streamed for online dictation is processed to produce text and then discarded — recordings are not retained.
- Offline dictation is processed entirely on your device using on-device models; nothing leaves your machine.
- Your transcript history, personal dictionary, and shortcuts are stored locally, under your control.
Infrastructure security
- Hosted on reputable cloud providers with strong physical and network security and their own compliance certifications.
- Network segmentation and firewalling between services.
- Secrets are managed through a dedicated secrets manager, never hardcoded.
- Automated, regularly tested backups for critical systems.
Access control
- Least-privilege access — staff get only what their role requires.
- Multi-factor authentication is enforced for internal systems and admin access.
- Access is logged and reviewed periodically.
Application security
- Secure software development practices and peer code review.
- Dependency scanning and prompt patching of known vulnerabilities.
- Desktop apps are code-signed and notarized so you can verify they come from us.
- Periodic security testing, including third-party assessments as the product matures.
Reliability
We monitor our systems continuously and maintain incident-response procedures. In the event of a security incident affecting your data, we will notify affected users and authorities as required by law.
Compliance
We align our practices with recognized frameworks and applicable data protection laws including GDPR and CCPA/CPRA. Business customers can request our Data Processing Agreement and review our subprocessors. Additional certifications and reports will be published here as they become available.
Report a vulnerability
We welcome responsible disclosure. If you believe you've found a security issue, email security@superlumy.comwith details and steps to reproduce. Please give us a reasonable opportunity to address the issue before public disclosure, and avoid accessing or modifying other users' data during your research.